Skill/Plugin Backdoor
Install a backdoored skill or plugin that persists across agent restarts
Tactic
Persistence (Stage 6)
Establish persistent access surviving restarts and session changes
Attack Class
SKILL-FRONTMATTER
Embedding malicious instructions in skill or plugin metadata and description fields
Evidence
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.
skill-backdoor-install
Honeypot Coverage (AgentPwn)
In scope for honeypot observation; trap page or telemetry hook not yet built.
Supply-chain trap page not yet built.
Evidence Source Breakdown
Evidence Timeline
HMA check SKILL-002 failed on fake-vulnerable-agent
HMA check SKILL-002 failed on fake-vulnerable-agent
HMA check SKILL-001 failed on opena2a/code-review-skill
HMA check SKILL-001 failed on opena2a/code-review-skill
HMA check SKILL-002 failed on fake-vulnerable-agent
HMA check SKILL-001 failed on damn-vulnerable-ai-agent
HMA check SKILL-001 failed on hackmyagent-release-test-vplv
Detection (HackMyAgent)
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
How to Cite
AI Agent Threat Matrix T-6004 (Skill/Plugin Backdoor). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6004